Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Apr 2017Siportal s.r.l.Siportal s.r.l. was fined by the Garante for retaining telephone and internet traffic data longer than permitted by law. The authority found this to be a breach of data protection rules.ITGaranteGDPR€30,000
06 Apr 2017Regione AbruzzoThe Garante fined Regione Abruzzo EUR 20,000 for unlawfully publishing lists on its website that revealed candidates' health status. The case involved the disclosure of sensitive personal data relating to individuals with disabilities.ITGaranteGDPR€20,000
06 Apr 2017CLARIMARKET S.L.CLARIMARKET S.L. was fined EUR 600 by the AEPD. The sanction concerned sending unsolicited commercial emails in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
31 Mar 2017B.B.B.B.B.B. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The emails continued despite repeated requests from the recipient to stop, which breached the LSSI.ESAEPDePrivacy€30,001
30 Mar 2017Acantho s.p.a.Acantho s.p.a. was fined by the Garante in the amount of EUR 30,000 for retaining telephone and telematic traffic data longer than legally permitted. The authority found this to be a breach of data protection rules.ITGaranteGDPR€30,000
30 Mar 2017Grand Hotel Des Bains s.r.l.Grand Hotel Des Bains s.r.l. was fined by the Garante 12,000 EUR for retaining surveillance footage longer than permitted under the video surveillance guidelines. The case concerns a breach of data retention rules for CCTV recordings.ITGaranteGDPR€12,000
30 Mar 2017Provincia di CasertaProvincia di Caserta was fined EUR 20,000 by the Garante. The authority found that the province failed to designate data processing officers and did not update the security program document required under the data protection code.ITGaranteGDPR€20,000
25 Mar 2017IMPACTING EMAIL MARKETING SOLUTIONS S.L.IMPACTING EMAIL MARKETING SOLUTIONS S.L. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent. The authority found this conduct to be in breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
23 Mar 2017Azienda Sanitaria ULSS 6 di VicenzaAzienda Sanitaria ULSS 6 di Vicenza was fined by the Garante 10,000 EUR for unlawfully communicating an individual's health data to the Comune di Arcugnano without proper authorization. The case involved a breach of lawful processing rules and safeguards for special-category data.ITGaranteGDPR€10,000
23 Mar 2017Ente Nazionale per L’Aviazione Civile (ENAC)ENAC was fined by the Garante in the amount of 10,000 EUR. The authority found that adequate security measures were not implemented, in breach of Articles 33 and 34 of the Italian Data Protection Code.ITGaranteGDPR€10,000
20 Mar 2017Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined EUR 10,000 by the HDPA. The authority found that the bank did not adequately satisfy the complainant’s right of access to recorded telephone conversations. The case concerned the legal obligation to provide access to such recordings.GRHDPAGDPR€10,000
16 Mar 2017ABELHAS.PT LIMITEDABELHAS.PT LIMITED was fined EUR 5,000 by the AEPD for failing to provide the required information and procedures to reject data processing on its website. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
16 Mar 2017Roma TPL s.c.a.r.l.Roma TPL s.c.a.r.l. was fined EUR 8,000 by the Garante for processing personal data through AVM systems on buses without full compliance with data protection rules. The case concerned improper use of monitoring and data-processing systems affecting passengers.ITGaranteGDPR€8,000
16 Mar 2017Welcome s.a.s. di Somma MicheleWelcome s.a.s. di Somma Michele was fined EUR 16,000 by the Garante for making unsolicited promotional calls. The authority found that the required privacy notice was not provided and consent was not obtained.ITGaranteGDPR€16,000
16 Mar 2017Obiettivo Ferrari s.r.l.Obiettivo Ferrari s.r.l. was fined by the Garante €16,000 for making an unsolicited promotional call. The company did not provide the required data protection information or obtain consent from the recipient.ITGaranteGDPR€16,000
16 Mar 2017Cigno d’Argento s.r.l.Cigno d’Argento s.r.l. was fined by the Garante 36,000 EUR for data protection violations. The case concerned the improper use of video surveillance systems without the required authorization.ITGaranteGDPR€36,000
14 Mar 2017GABINETE PARAPSICOLOGICO MYSTIC S.L.GABINETE PARAPSICOLOGICO MYSTIC S.L. was fined by the AEPD for sending unsolicited commercial SMS messages. The authority found that recipients were not given a simple and free opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€7,100
09 Mar 2017Moto One s.r.l.Moto One s.r.l. was fined by the Garante in the amount of 14,400 EUR for violations related to its video surveillance system. The authority found that recorded images were retained longer than permitted and that required informational signage was missing.ITGaranteGDPR€14,400
08 Mar 2017Elliniki Etaireia Systimikon MeletonThe company was fined by the HDPA for illegally collecting and using personal data for direct marketing purposes. The infringement involved unsolicited electronic communications sent without prior consent from the data subjects.GRHDPAePrivacy€3,000
02 Mar 2017MM Group s.r.l.MM Group s.r.l. was fined EUR 20,000 by the Garante for making unsolicited promotional calls. The calls were placed to a number listed in the public opt-out register, which breached data protection rules.ITGaranteGDPR€20,000